2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-20036CRITICAL9.9A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands w...
CVE-2023-20004MEDIUM4.4Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to ove...
CVE-2023-20154HIGH8.1A vulnerability in the external authentication mechanism of Cisco Modeling Labs could allow an unauthenticated, remote a...
CVE-2023-20125HIGH8.6A vulnerability in the local interface of Cisco BroadWorks Network Server could allow an unauthenticated, remote attacke...
CVE-2023-4348Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-4679MEDIUM5.5A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del functi...
CVE-2023-2332MEDIUM4.8A stored Cross-site Scripting (XSS) vulnerability exists in the Conditions tab of Pricing Rules in pimcore/pimcore versi...
CVE-2023-0737MEDIUM6.5wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily d...
CVE-2023-0109MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability all...
CVE-2023-4458HIGH7.5A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack o...
CVE-2023-4134MEDIUM5.5A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device...
CVE-2023-34049MEDIUM6.7The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force ...
CVE-2023-38920MEDIUM4.8Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary co...
CVE-2023-35686HIGH7.8In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This...
CVE-2023-35659HIGH7.8In DevmemIntChangeSparse of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the...
CVE-2023-52268CRITICAL9.1The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user...
CVE-2023-50176HIGH8.8A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allo...
CVE-2023-47543HIGH8.1An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 throug...
CVE-2023-44255MEDIUM4.1An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnal...
CVE-2023-32736HIGH7.3A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMAT...
CVE-2023-40457The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected...
CVE-2023-27195CRITICAL9.8Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func=UserfromUUID&uuid= to retrieve th...
CVE-2023-1973HIGH7.5A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of ...
CVE-2023-1932MEDIUM6.1A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators....
CVE-2023-29126HIGH8.8The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force pro...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now